Poor cybersecurity in the US Federal Aviation Administration is putting aircraft communication channels at risk of attack, government auditors have warned.
The same day an accidental cable cut knocked telecommunication equipment offline on the US East Coast, the US Government Accountability Office (GAO) said issues with authentication, encryption, and protocol design risked causing similar incidents.
A GAO report on aviation cybersecurity said communications through the FAA’s two text-based applications, ACARS and CPDLC, were “generally not encrypted and lack authentication… [and] vulnerable to interception, spoofing, and flood-based denial-of-service attacks.”
Investigators said the organisation had partially addressed some of GAO’s prior cybersecurity concerns and identified cybersecurity threats to the national airspace (NAS), but “has not fully implemented key elements of a risk-based cybersecurity program.”